SV-238441r667497_rule
V-238441
SRG-APP-000133-DB-000362
O112-C2-003700
CAT II
10
Restrict developer privileges to production objects to only objects and data where those privileges are required and authorized. Document the approval and risk acceptance.
Consider using separate accounts for a person's developer duties and production duties. At a minimum, use separate roles for developer privileges and production privileges.
If developers need the ability to create and maintain tables (or other database objects) as part of their development activities, provide dedicated tablespaces, and revoke any rights that allowed them to use production tablespaces for this purpose.
Check the production system to ensure no developer accounts have rights to modify the production database structure or alter production data.
If developer accounts with these rights exist, ask for documentation that shows these accounts have formal approval and risk acceptance. If this documentation does not exist, this is a finding.
If developer accounts exist with the right to create and maintain tables (or other database objects) in production tablespaces, this is a finding.
V-238441
False
O112-C2-003700
Check the production system to ensure no developer accounts have rights to modify the production database structure or alter production data.
If developer accounts with these rights exist, ask for documentation that shows these accounts have formal approval and risk acceptance. If this documentation does not exist, this is a finding.
If developer accounts exist with the right to create and maintain tables (or other database objects) in production tablespaces, this is a finding.
M
4057